equinor / fusion-workspace

https://equinor.github.io/fusion-workspace/
MIT License
8 stars 1 forks source link

[Snyk] Upgrade @equinor/eds-core-react from 0.27.0 to 0.35.1 #582

Closed ken-mellem closed 5 months ago

ken-mellem commented 5 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade @equinor/eds-core-react from 0.27.0 to 0.35.1.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **26 versions** ahead of your current version. - The recommended version was released **2 months ago**, on 2023-12-21. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Missing Release of Resource after Effective Lifetime
[SNYK-JS-INFLIGHT-6095116](https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116) | **141/1000**
**Why?** Confidentiality impact: None, Integrity impact: None, Availability impact: High, Scope: Unchanged, Exploit Maturity: Proof of Concept, User Interaction (UI): None, Privileges Required (PR): None, Attack Complexity: Low, Attack Vector: Local, EPSS: 0.01055, Social Trends: No, Days since published: 69, Reachable: No, Transitive dependency: Yes, Is Malicious: No, Business Criticality: High, Provider Urgency: Medium, Package Popularity Score: 99, Impact: 5.99, Likelihood: 2.35, Score Version: V5 | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: @equinor/eds-core-react
  • 0.35.1 - 2023-12-21

    [0.35.1] - 2023-12-21

    Fixed

    • 🐛 Typography: Bug affecting users of styled-components v6 where line-clamping would be applied to all Typography elements on the page if the lines prop was set on one of them by @ oddvernes in #3193
  • 0.35.0 - 2023-12-13

    [0.35.0] - 2023-12-13

    Added

    • Icon: Added support for multiple paths (type IconData.svgPathData is now string | Array<string>) by @ oddvernes in #3177

    Fixed

    • 🐛 Autocomplete: Fixed scrollbar clipping issue that manifested in Firefox by @ oddvernes in #3179
    • 🐛 Slider: Fixed a bug where label tooltip was always visible for users with styled-components@5.x.x by @ oddvernes in #3173

    Changed

    • 🧑‍💻 SideSheet: open prop type changed to required, conditionally render title and close button to reflect the optional types of title and onClose props by @ oddvernes in #3161

    Full Changelog: https://github.com/equinor/design-system/compare/eds-core-react@0.34.0...eds-core-react@0.35.0

  • 0.34.0 - 2023-11-17

    [0.34.0] - 2023-11-17

    Added

    Changed

    Fixed

    • 📱 Slider: added touch support for range slider by @ oddvernes in #3144
    • 🐛 Slider: fixed bug in Safari where slider would grow in width on mouseover by @ oddvernes in #3145
  • 0.33.1 - 2023-10-20

    [0.33.1] - 2023-10-20

    Fixed

    • 🐛Chip: only hover color when clickable (fixed for error variant) by @ oddvernes in #3096
    • 🐛 Table.Row: fix Styled-components v6 printing a false positive console warning about active prop by @ oddvernes in #3104
    • 🐛 Slider: change returnvalue type for onChange and onChangeCommitted from number[] | number to number[] to reflect reality. And allow value for non-range slider to be number[] (an array with only one number) by @ oddvernes in #3076
    • ⬆️ Update @ babel/runtime to fix a vulnerability in its dependency @ babel/traverse (https://nvd.nist.gov/vuln/detail/CVE-2023-45133) by @ oddvernes in #3115

    Full Changelog: https://github.com/equinor/design-system/compare/eds-core-react@0.33.0...eds-core-react@0.33.1

  • 0.33.0 - 2023-09-26
  • 0.32.4 - 2023-08-15
  • 0.32.3 - 2023-07-14
  • 0.32.3-dev20230714 - 2023-07-14
  • 0.32.2 - 2023-07-13
  • 0.32.2-dev-rollup-test.1 - 2023-07-12
  • 0.32.1 - 2023-07-11
  • 0.32.1-dev20230711 - 2023-07-11
  • 0.32.0 - 2023-07-10
  • 0.32.0-dev07102023 - 2023-07-10
  • 0.32.0-dev07072023 - 2023-07-10
  • 0.31.1 - 2023-04-25
  • 0.31.0 - 2023-04-25
  • 0.30.0 - 2023-03-15
  • 0.29.2-dev14022023 - 2023-02-14
  • 0.29.2-dev09022023 - 2023-02-09
  • 0.29.1 - 2023-02-03
  • 0.29.1-DEV03022023 - 2023-02-03
  • 0.29.0 - 2023-02-03
  • 0.28.0 - 2022-12-21
  • 0.28.0-dev12152022 - 2022-12-15
  • 0.28.0-dev12052022 - 2022-12-13
  • 0.27.0 - 2022-11-17
from @equinor/eds-core-react GitHub release notes

**Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/project-portal-agk/project/6349c3df-ad07-48e8-87ec-8172c2aba36e?utm_source=github&utm_medium=referral&page=upgrade-pr) 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/project-portal-agk/project/6349c3df-ad07-48e8-87ec-8172c2aba36e/settings/integration?utm_source=github&utm_medium=referral&page=upgrade-pr) 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/project-portal-agk/project/6349c3df-ad07-48e8-87ec-8172c2aba36e/settings/integration?pkg=@equinor/eds-core-react&utm_source=github&utm_medium=referral&page=upgrade-pr#auto-dep-upgrades)